<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Why Did Strict IP Address Check Break this VPN? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/why-did-strict-ip-address-check-break-this-vpn/m-p/196747#M58565</link>
    <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;IKE Gateway Local IP Address 216.1.x.x Peer IPA 199.79.x.x&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;IPSec Tunnel used Proxy ID which was Local 172.16.2x.x (Internal Server IP of 10.x.x.x was NATd) Remote 128.1.2xx.x&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 25 Jan 2018 15:32:10 GMT</pubDate>
    <dc:creator>ms.jzam</dc:creator>
    <dc:date>2018-01-25T15:32:10Z</dc:date>
    <item>
      <title>Why Did Strict IP Address Check Break this VPN?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/why-did-strict-ip-address-check-break-this-vpn/m-p/196727#M58561</link>
      <description>&lt;P&gt;We have been working with TAC to find the cause of this issue where FTP client could no longer upload to external companies FTP server over the VPN tunnel.&amp;nbsp; After many days, we started a packet filter on the Public Internet (WAN) interface, which is a different zone from the tunnel interface, and were still seeing drops due to "flow_dos_pf_strictip".&amp;nbsp; We had previously disabled the zone_protection policy that was applied to the tunnel interface zone, and even though we did not see drops, the uploads were failing.&amp;nbsp; When we finally did that packet filter on the WAN interface we saw the drops again due to the same reason "flow_dos_pf_strictip" and decided to remove the zone protection policy from the WAN interface.&amp;nbsp; BOOM!&amp;nbsp; FTP uploads succeed.&amp;nbsp; Combing through the policy I saw the strict ip check option and removed it, then pushed the policy overwriting our revert.&amp;nbsp; Everything still good.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We couldn't find the configuration change that put that feature in place (wish that function worked better in the Palo, or just knew how to use it better!) and reading the KB pages for that feature, I'm not sure why it was causing our traffic to be dropped.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any help would be very much appreciated!&lt;/P&gt;</description>
      <pubDate>Wed, 24 Jan 2018 21:25:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/why-did-strict-ip-address-check-break-this-vpn/m-p/196727#M58561</guid>
      <dc:creator>ms.jzam</dc:creator>
      <dc:date>2018-01-24T21:25:44Z</dc:date>
    </item>
    <item>
      <title>Re: Why Did Strict IP Address Check Break this VPN?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/why-did-strict-ip-address-check-break-this-vpn/m-p/196744#M58564</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/70110"&gt;@ms.jzam&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;What IP address were you sending to from within that tunnel? If I had to harbor a guess, the IP in question is technically not valid if you follow&amp;nbsp;RFC 1918.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 24 Jan 2018 22:06:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/why-did-strict-ip-address-check-break-this-vpn/m-p/196744#M58564</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2018-01-24T22:06:51Z</dc:date>
    </item>
    <item>
      <title>Re: Why Did Strict IP Address Check Break this VPN?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/why-did-strict-ip-address-check-break-this-vpn/m-p/196747#M58565</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;IKE Gateway Local IP Address 216.1.x.x Peer IPA 199.79.x.x&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;IPSec Tunnel used Proxy ID which was Local 172.16.2x.x (Internal Server IP of 10.x.x.x was NATd) Remote 128.1.2xx.x&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 25 Jan 2018 15:32:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/why-did-strict-ip-address-check-break-this-vpn/m-p/196747#M58565</guid>
      <dc:creator>ms.jzam</dc:creator>
      <dc:date>2018-01-25T15:32:10Z</dc:date>
    </item>
    <item>
      <title>Re: Why Did Strict IP Address Check Break this VPN?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/why-did-strict-ip-address-check-break-this-vpn/m-p/197513#M58720</link>
      <description>&lt;P&gt;BUMP&lt;/P&gt;</description>
      <pubDate>Mon, 29 Jan 2018 23:43:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/why-did-strict-ip-address-check-break-this-vpn/m-p/197513#M58720</guid>
      <dc:creator>ms.jzam</dc:creator>
      <dc:date>2018-01-29T23:43:02Z</dc:date>
    </item>
    <item>
      <title>Re: Why Did Strict IP Address Check Break this VPN?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/why-did-strict-ip-address-check-break-this-vpn/m-p/197621#M58745</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/70110"&gt;@ms.jzam&lt;/a&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Same here I had to take zone protection off of my untrust zone cause it was breaking my VPN. I will have to try deselecting strict IP check and see if it fixes my issue&lt;/P&gt;</description>
      <pubDate>Tue, 30 Jan 2018 15:55:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/why-did-strict-ip-address-check-break-this-vpn/m-p/197621#M58745</guid>
      <dc:creator>jdprovine</dc:creator>
      <dc:date>2018-01-30T15:55:48Z</dc:date>
    </item>
    <item>
      <title>Re: Why Did Strict IP Address Check Break this VPN?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/why-did-strict-ip-address-check-break-this-vpn/m-p/197622#M58746</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/18719"&gt;@jdprovine&lt;/a&gt;&amp;nbsp; Let us know what you find!&amp;nbsp; If it does fix the issue, that's a much better place to be than disabling the whole ZP policy.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hopefully we can get some progress on understanding the root cause behind the issue.&lt;/P&gt;</description>
      <pubDate>Tue, 30 Jan 2018 16:02:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/why-did-strict-ip-address-check-break-this-vpn/m-p/197622#M58746</guid>
      <dc:creator>ms.jzam</dc:creator>
      <dc:date>2018-01-30T16:02:20Z</dc:date>
    </item>
    <item>
      <title>Re: Why Did Strict IP Address Check Break this VPN?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/why-did-strict-ip-address-check-break-this-vpn/m-p/197623#M58747</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/70110"&gt;@ms.jzam&lt;/a&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have a ticket in with TAC about it and so far they told me that it wasn't likely the cause of my VPN breaking though yesterday I was able to repeat the issue by merely enabling Zone protection. I would be very interested to see why the strict IP address cause the issue. TAC also advised me to turn on spoofing IP address, which did not work.&lt;/P&gt;</description>
      <pubDate>Tue, 30 Jan 2018 16:06:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/why-did-strict-ip-address-check-break-this-vpn/m-p/197623#M58747</guid>
      <dc:creator>jdprovine</dc:creator>
      <dc:date>2018-01-30T16:06:00Z</dc:date>
    </item>
    <item>
      <title>Re: Why Did Strict IP Address Check Break this VPN?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/why-did-strict-ip-address-check-break-this-vpn/m-p/197652#M58749</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/18719"&gt;@jdprovine&lt;/a&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I would reccommend taking the same steps that I did in order to get a clue as to the cause.&amp;nbsp; Include your VPN tunnel network/interface in a packet capture filter, and also your WAN interface where the VPN traffic is coming into.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;clear logs and packet filter&lt;/P&gt;&lt;P&gt;debug dataplane packet-diag clear all&lt;/P&gt;&lt;P&gt;debug dataplane packet-diag clear log log&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;enable debug&lt;/P&gt;&lt;P&gt;debug dataplane packet-diag set log feature flow basic&lt;/P&gt;&lt;P&gt;debug dataplane packet-diag set log on&lt;/P&gt;&lt;P&gt;debug dataplane packet-diag set log off&lt;/P&gt;&lt;P&gt;debug dataplane packet-diag aggregate-logs&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;review logs&lt;/P&gt;&lt;P&gt;less dp-log pan_packet_diag.log&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;clear your vpn tunnels and see if interesting traffic reestablishes them&lt;/P&gt;&lt;P&gt;clear vpn ike-sa&amp;nbsp;&lt;/P&gt;&lt;P&gt;clear vpn ipsec-sa&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;check and configure your packet filter&lt;/P&gt;&lt;P&gt;debug dataplane packet-diag show setting&amp;nbsp;&lt;/P&gt;&lt;P&gt;*was easier for me to configure the packet filter in the&amp;nbsp;WEB-UI&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;check for vpn sesssions&lt;/P&gt;&lt;P&gt;show session all filter source X destination X&lt;/P&gt;&lt;P&gt;show vpn flow&lt;/P&gt;&lt;P&gt;*pay attention for encap and decap byte increase&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;check the details of the specific traffic session&lt;/P&gt;&lt;P&gt;show session id X&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;show results of the packet filter&lt;/P&gt;&lt;P&gt;show counter global filter packet-filter yes delta yes&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;There is probably a better order to running these commands, but this is everything I used to try and get to a resolution.&lt;/P&gt;</description>
      <pubDate>Tue, 30 Jan 2018 16:59:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/why-did-strict-ip-address-check-break-this-vpn/m-p/197652#M58749</guid>
      <dc:creator>ms.jzam</dc:creator>
      <dc:date>2018-01-30T16:59:54Z</dc:date>
    </item>
    <item>
      <title>Re: Why Did Strict IP Address Check Break this VPN?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/why-did-strict-ip-address-check-break-this-vpn/m-p/197654#M58751</link>
      <description>&lt;P&gt;There may be something in your Zone Protection Profiles that is configured other than what you are intending.&amp;nbsp; For example out of order packets or asymetric routing (just examples).&lt;/P&gt;&lt;P&gt;From the CLI you can type out these commands and it will give you a good config dump of what your profiles look like.&amp;nbsp; It may help to sanitize them and paste them for people to take a look at.&lt;/P&gt;&lt;P&gt;&lt;FONT color="#0000ff"&gt;pa-firewall&amp;gt; set cli config-output-format set&lt;/FONT&gt;&amp;nbsp;&amp;nbsp; (this sets the way the output will be displayed and only lasts the current session)&lt;/P&gt;&lt;P&gt;&lt;FONT color="#0000ff"&gt;pa-firewall&amp;gt; configure&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#0000ff"&gt;pa-firewall# show network profiles zone-protection-profile&lt;/FONT&gt;&amp;nbsp; (this will display the profiles in line format, not xml)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I try to use this to make sure what is being put in is actually doing what I want (if anyone remembers back in the cisco "gui" days *cough*pix*cough*).&lt;/P&gt;</description>
      <pubDate>Tue, 30 Jan 2018 17:27:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/why-did-strict-ip-address-check-break-this-vpn/m-p/197654#M58751</guid>
      <dc:creator>BrianRa</dc:creator>
      <dc:date>2018-01-30T17:27:29Z</dc:date>
    </item>
    <item>
      <title>Re: Why Did Strict IP Address Check Break this VPN?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/why-did-strict-ip-address-check-break-this-vpn/m-p/197657#M58753</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/49049"&gt;@BrianRa&lt;/a&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;ran the commands as you indicate but received no output:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;PRE&gt;(active)&amp;gt; 
(active)&amp;gt; set cli config-output-format set
(active)&amp;gt; configure
Entering configuration mode
[edit]                                                                                                                                            
(active)# show network profiles zone-protection-profile 
  &amp;lt;name&amp;gt;   &amp;lt;name&amp;gt;
  |        Pipe through a command
  &amp;lt;Enter&amp;gt;  Finish input

(active)# show network profiles zone-protection-profile 
set network profiles zone-protection-profile 
[edit]                                                                                                                                            
(active)# show network profiles zone-protection-profile ZP_DEFAULT_OUT
[edit]                                                                                                                                            
(active)#&lt;/PRE&gt;&lt;P&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 30 Jan 2018 17:35:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/why-did-strict-ip-address-check-break-this-vpn/m-p/197657#M58753</guid>
      <dc:creator>ms.jzam</dc:creator>
      <dc:date>2018-01-30T17:35:04Z</dc:date>
    </item>
    <item>
      <title>Re: Why Did Strict IP Address Check Break this VPN?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/why-did-strict-ip-address-check-break-this-vpn/m-p/197659#M58755</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/70110"&gt;@ms.jzam&lt;/a&gt;&amp;nbsp;do you currently have the profiles running on the firewall?&amp;nbsp; If not they will not show up in the current configuration.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Also if you are pushing from Panorama then they will not show up on the local firewall configuration (sorry I didn't think to mention this before).&amp;nbsp; These configs can be shown on the local firewall however they only show as xml (there is no option to change this).&lt;/P&gt;&lt;P&gt;&lt;FONT color="#0000ff"&gt;pa-firewall&amp;gt; show config pushed-template&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#0000ff"&gt;pa-firewall&amp;gt;&amp;nbsp;show config pushed-shared-policy&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;From Panorama CLI you can view these as well but it is more convoluted to get to a specific firewall config.&lt;/P&gt;&lt;P&gt;&lt;FONT color="#0000ff"&gt;Panorama&amp;gt; set cli config-output-format set&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#0000ff"&gt;Panorama# show device-group &lt;STRONG&gt;&amp;lt;pa-firewall&amp;gt;&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#0000ff"&gt;Panorama# show template &lt;STRONG&gt;&amp;lt;pa-firewall&amp;gt;&lt;/STRONG&gt; config network profiles zone-protection-profile&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 30 Jan 2018 17:56:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/why-did-strict-ip-address-check-break-this-vpn/m-p/197659#M58755</guid>
      <dc:creator>BrianRa</dc:creator>
      <dc:date>2018-01-30T17:56:57Z</dc:date>
    </item>
    <item>
      <title>Re: Why Did Strict IP Address Check Break this VPN?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/why-did-strict-ip-address-check-break-this-vpn/m-p/197660#M58756</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/49049"&gt;@BrianRa&lt;/a&gt;&amp;nbsp; yes it was because of Panorama!&amp;nbsp; Thanks!&lt;/P&gt;</description>
      <pubDate>Tue, 30 Jan 2018 18:04:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/why-did-strict-ip-address-check-break-this-vpn/m-p/197660#M58756</guid>
      <dc:creator>ms.jzam</dc:creator>
      <dc:date>2018-01-30T18:04:46Z</dc:date>
    </item>
    <item>
      <title>Re: Why Did Strict IP Address Check Break this VPN?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/why-did-strict-ip-address-check-break-this-vpn/m-p/198295#M58873</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/18719"&gt;@jdprovine&lt;/a&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Anything new on this?&lt;/P&gt;</description>
      <pubDate>Thu, 01 Feb 2018 17:40:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/why-did-strict-ip-address-check-break-this-vpn/m-p/198295#M58873</guid>
      <dc:creator>ms.jzam</dc:creator>
      <dc:date>2018-02-01T17:40:21Z</dc:date>
    </item>
    <item>
      <title>Re: Why Did Strict IP Address Check Break this VPN?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/why-did-strict-ip-address-check-break-this-vpn/m-p/198296#M58874</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/70110"&gt;@ms.jzam&lt;/a&gt;&lt;/P&gt;&lt;P&gt;I am trying to find a maintenance window to test and collect logs and do a packet capture. I am hoping maybe i will get luck tomorrow morning though unlike other places I have worked most users are on the VPN during the work day instead of the off shift or I would have done it by now LOL &lt;span class="lia-unicode-emoji" title=":face_with_tongue:"&gt;😛&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 01 Feb 2018 17:44:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/why-did-strict-ip-address-check-break-this-vpn/m-p/198296#M58874</guid>
      <dc:creator>jdprovine</dc:creator>
      <dc:date>2018-02-01T17:44:09Z</dc:date>
    </item>
    <item>
      <title>Re: Why Did Strict IP Address Check Break this VPN?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/why-did-strict-ip-address-check-break-this-vpn/m-p/198514#M58913</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/70110"&gt;@ms.jzam&lt;/a&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Amazing the VPN started to work again when I deselected Strict IP Address Check.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 02 Feb 2018 13:24:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/why-did-strict-ip-address-check-break-this-vpn/m-p/198514#M58913</guid>
      <dc:creator>jdprovine</dc:creator>
      <dc:date>2018-02-02T13:24:45Z</dc:date>
    </item>
    <item>
      <title>Re: Why Did Strict IP Address Check Break this VPN?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/why-did-strict-ip-address-check-break-this-vpn/m-p/198547#M58930</link>
      <description>&lt;P&gt;Ok that's two confirmations on fixing the issue.&amp;nbsp; I think this deserves to be bumped until we can sniff out a solid understanding of what's happening here.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;BUMP!&lt;/P&gt;</description>
      <pubDate>Fri, 02 Feb 2018 15:35:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/why-did-strict-ip-address-check-break-this-vpn/m-p/198547#M58930</guid>
      <dc:creator>ms.jzam</dc:creator>
      <dc:date>2018-02-02T15:35:23Z</dc:date>
    </item>
    <item>
      <title>Re: Why Did Strict IP Address Check Break this VPN?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/why-did-strict-ip-address-check-break-this-vpn/m-p/198567#M58936</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/70110"&gt;@ms.jzam&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;I would love to help on this but unfortenately I can't reproduce the issue at all. Unfortanetly the only way you can enable Packet Drop Logging is if your device is in Common Criteria (CCEAL4 Mode), which I&amp;nbsp;&lt;EM&gt;doubt&lt;/EM&gt; yours are; that would be something to check out though, because if they are you might get your&amp;nbsp;&lt;EM&gt;why&lt;/EM&gt; answer.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 02 Feb 2018 15:59:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/why-did-strict-ip-address-check-break-this-vpn/m-p/198567#M58936</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2018-02-02T15:59:22Z</dc:date>
    </item>
    <item>
      <title>Re: Why Did Strict IP Address Check Break this VPN?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/why-did-strict-ip-address-check-break-this-vpn/m-p/198569#M58938</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Happy to provide more detailed configuration for any attempts at duplicating the issue.&amp;nbsp; What&amp;nbsp;would be needed?&lt;/P&gt;</description>
      <pubDate>Fri, 02 Feb 2018 16:05:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/why-did-strict-ip-address-check-break-this-vpn/m-p/198569#M58938</guid>
      <dc:creator>ms.jzam</dc:creator>
      <dc:date>2018-02-02T16:05:06Z</dc:date>
    </item>
    <item>
      <title>Re: Why Did Strict IP Address Check Break this VPN?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/why-did-strict-ip-address-check-break-this-vpn/m-p/198572#M58939</link>
      <description>&lt;P&gt;The exact ZP settings that you actually had selected at the time you ran into the issue; along with how you actually have the tunnel configured and the IP ranges being used on both sides. Then it would just be how your VPN was actually setup and configured. If you feel more comfortable sending this directly and not posting it on the forum just let me know and you can just email it over to me.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 02 Feb 2018 16:10:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/why-did-strict-ip-address-check-break-this-vpn/m-p/198572#M58939</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2018-02-02T16:10:06Z</dc:date>
    </item>
    <item>
      <title>Re: Why Did Strict IP Address Check Break this VPN?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/why-did-strict-ip-address-check-break-this-vpn/m-p/198580#M58941</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;&amp;nbsp; I tried to find a DM feature, don't think there is one.&amp;nbsp; Happy to continue over email.&lt;/P&gt;</description>
      <pubDate>Fri, 02 Feb 2018 16:53:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/why-did-strict-ip-address-check-break-this-vpn/m-p/198580#M58941</guid>
      <dc:creator>ms.jzam</dc:creator>
      <dc:date>2018-02-02T16:53:22Z</dc:date>
    </item>
  </channel>
</rss>

